-
Notifications
You must be signed in to change notification settings - Fork 512
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Security Content] 8.3 Add Investigation Guides - 3 #1990
Conversation
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Approving so it is ready to merge when needed.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Left some comments for your consideration. Thanks for your work on this @w0rk3r !
rules/windows/defense_evasion_clearing_windows_console_history.toml
Outdated
Show resolved
Hide resolved
rules/windows/defense_evasion_enable_network_discovery_with_netsh.toml
Outdated
Show resolved
Hide resolved
rules/windows/defense_evasion_clearing_windows_security_logs.toml
Outdated
Show resolved
Hide resolved
Co-authored-by: nastasha-solomon <[email protected]>
Hey @nastasha-solomon & @joepeeples, can I get a final review on this one to merge? |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Added a few small suggestions, but otherwise LGTM!
rules/windows/defense_evasion_enable_network_discovery_with_netsh.toml
Outdated
Show resolved
Hide resolved
rules/windows/defense_evasion_powershell_windows_firewall_disabled.toml
Outdated
Show resolved
Hide resolved
rules/windows/lateral_movement_executable_tool_transfer_smb.toml
Outdated
Show resolved
Hide resolved
Co-authored-by: Joe Peeples <[email protected]>
* [Security Content] 8.3 Add Investigation Guides - 3 * bump date * Apply suggestions from code review Co-authored-by: nastasha-solomon <[email protected]> * Apply suggestions from code review Co-authored-by: Joe Peeples <[email protected]> Co-authored-by: nastasha-solomon <[email protected]> Co-authored-by: Joe Peeples <[email protected]> (cherry picked from commit 27f5c2e)
* [Security Content] 8.3 Add Investigation Guides - 3 * bump date * Apply suggestions from code review Co-authored-by: nastasha-solomon <[email protected]> * Apply suggestions from code review Co-authored-by: Joe Peeples <[email protected]> Co-authored-by: nastasha-solomon <[email protected]> Co-authored-by: Joe Peeples <[email protected]> (cherry picked from commit 27f5c2e)
* [Security Content] 8.3 Add Investigation Guides - 3 * bump date * Apply suggestions from code review Co-authored-by: nastasha-solomon <[email protected]> * Apply suggestions from code review Co-authored-by: Joe Peeples <[email protected]> Co-authored-by: nastasha-solomon <[email protected]> Co-authored-by: Joe Peeples <[email protected]> (cherry picked from commit 27f5c2e)
* [Security Content] 8.3 Add Investigation Guides - 3 * bump date * Apply suggestions from code review Co-authored-by: nastasha-solomon <[email protected]> * Apply suggestions from code review Co-authored-by: Joe Peeples <[email protected]> Co-authored-by: nastasha-solomon <[email protected]> Co-authored-by: Joe Peeples <[email protected]> (cherry picked from commit 27f5c2e)
* [Security Content] 8.3 Add Investigation Guides - 3 * bump date * Apply suggestions from code review Co-authored-by: nastasha-solomon <[email protected]> * Apply suggestions from code review Co-authored-by: Joe Peeples <[email protected]> Co-authored-by: nastasha-solomon <[email protected]> Co-authored-by: Joe Peeples <[email protected]> (cherry picked from commit 27f5c2e)
* [Security Content] 8.3 Add Investigation Guides - 3 * bump date * Apply suggestions from code review Co-authored-by: nastasha-solomon <[email protected]> * Apply suggestions from code review Co-authored-by: Joe Peeples <[email protected]> Co-authored-by: nastasha-solomon <[email protected]> Co-authored-by: Joe Peeples <[email protected]> (cherry picked from commit 27f5c2e)
* [Security Content] 8.3 Add Investigation Guides - 3 * bump date * Apply suggestions from code review Co-authored-by: nastasha-solomon <[email protected]> * Apply suggestions from code review Co-authored-by: Joe Peeples <[email protected]> Co-authored-by: nastasha-solomon <[email protected]> Co-authored-by: Joe Peeples <[email protected]> (cherry picked from commit 27f5c2e)
Summary
Adds Investigation guides to the following rules: